Empowerreg Corp. (“Empowerreg,” “we,” “us,” or “our”), respects your privacy and is committed to protecting personal information. This Privacy Policy (the “Policy”) describes how we collect, use, disclose, store, and otherwise process personal information when you interact with the Empowerreg website, software applications, dashboards, integrations, complaint-management tools, post-market-surveillance tools, risk-management features, reports, analytics, artificial intelligence-enabled features, and related products and services (collectively, the “Services”).
This Policy is incorporated into and subject to the Empowerreg Terms of Service. It applies to:
This Policy does not modify any contractual obligations concerning Customer Content under an applicable services agreement, Terms of Service, order form, statement of work, data processing agreement, business associate agreement, or other written agreement governing the Services. Where Empowerreg processes personal information on behalf of a customer, Empowerreg generally acts as a service provider, processor, or similar intermediary and processes that information under the customer’s instructions and applicable agreement.
A. Information You Provide Directly
We may collect information you voluntarily provide when you:
This information may include:
B. Customer Content and Integration Data
In connection with providing the Services, customers may submit, upload, synchronize, transmit, integrate, or otherwise make available product, quality, regulatory, and post-market information, records, documentation, reports, prompts, requests, communications, and other content (“Customer Content”).
Depending on how the Services are used, Customer Content may include:
Empowerreg processes Customer Content on behalf of customers in accordance with applicable agreements and customer instructions. Customers are responsible for obtaining the permissions, authorizations, consents, and rights necessary to provide Customer Content to Empowerreg and to authorize Empowerreg’s access to any customer-authorized third-party services.
Customers should not provide protected health information (“PHI”) through the Services unless the applicable Service supports the processing of PHI and Empowerreg and the customer have entered into a business associate agreement where required. Where a business associate agreement applies, it governs Empowerreg’s processing of PHI.
C. Information Collected Automatically
When you use the Services, we may automatically collect technical and usage information, including:
We may use cookies, pixels, analytics tools, session technologies, and similar technologies to operate, secure, maintain, and improve the Services; authenticate users; remember preferences; and understand how the Services are used. You may be able to control certain cookies through your browser settings, although disabling cookies may affect the availability or functionality of some features.
We may use personal information and Customer Content, as applicable, to:
When Empowerreg processes Customer Content on behalf of a Customer, we process that information for the purposes and under the instructions specified in the applicable agreement with that Customer.
The Services may use artificial intelligence, machine learning, predictive analytics, automation technologies, and related technologies (“AI Technologies”) to generate documentation, analyses, summaries, alerts, classifications, recommendations, risk insights, trend analyses, complaint-management support, reportability-support information, and other outputs (“Outputs”).
Outputs are probabilistic in nature and may be inaccurate, incomplete, outdated, biased, or otherwise unreliable. Outputs are intended to assist Customer’s regulatory, quality, product, and post-market activities; they are not a substitute for Customer’s independent judgment or professional review.
We do not use Customer-specific confidential information, Customer Content, or regulated information to train a publicly available or general-purpose artificial intelligence model for the benefit of unrelated third parties without Customer’s authorization. Subject to applicable law and any applicable BAA, we may use aggregated, anonymized, or de-identified information to improve and develop the Services and AI Technologies.
We may share personal information and Customer Content, as applicable:
We require service providers that process personal information on our behalf to use it only for authorized purposes and to protect it appropriately. Where PHI is involved, applicable BAA requirements govern the use of subcontractors and service providers.
We do not sell personal information or share personal information for cross-context behavioral advertising.
We may aggregate, anonymize, or de-identify information collected through the Services so that it can no longer reasonably identify an individual or a specific Customer. Subject to applicable law and any applicable BAA, we may use and disclose aggregated or de-identified information for lawful business purposes, including analytics, benchmarking, research, product development, marketing, and improvement of the Services and AI Technologies.
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information processed through the Services against unauthorized access, use, disclosure, alteration, or destruction.
No method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee that unauthorized third parties will never be able to defeat our safeguards or improperly access, collect, use, or disclose information. Where Empowerreg processes PHI under an applicable BAA, the safeguards and incident-related obligations in that BAA also apply.
Empowerreg may process protected health information (“PHI”) only where the applicable Service supports that processing and Empowerreg and the applicable Customer have entered into a business associate agreement (“BAA”) as required by HIPAA. This Privacy Policy is not a business associate agreement and does not replace any BAA. If Empowerreg processes PHI under a BAA, the BAA governs Empowerreg’s use and disclosure of PHI and controls over any conflicting provision of this Policy. Where Empowerreg processes PHI or other personal information on behalf of a Customer, the Customer is responsible for providing any required privacy notices, obtaining any required consents or authorizations, and responding to individual requests, except to the extent Empowerreg is required to assist under an applicable BAA or other written agreement.
We retain personal information for as long as reasonably necessary to:
When Empowerreg processes Customer Content on behalf of a Customer, we retain that information in accordance with the applicable agreement and Customer’s instructions, subject to applicable law and legitimate backup, security, and legal-retention needs.
We may retain aggregated or de-identified information indefinitely.
The Services are operated in the United States. If you access or use the Services from outside the United States, your information may be transferred to, processed in, and stored in the United States and other jurisdictions whose data-protection laws may differ from those in your jurisdiction.
Where required by applicable law, we take reasonable measures designed to protect personal information transferred internationally in accordance with this Policy and applicable law.
Depending on your jurisdiction and the nature of Empowerreg’s relationship to the applicable information, you may have rights regarding your personal information, including the right to:
You may review, update, or request deletion of certain Account Information by contacting us using the information below.
If Empowerreg processes your personal information on behalf of a Customer, you should direct your request to that Customer. Empowerreg will assist Customers with such requests as required by applicable law and the applicable agreement.
If you are a California resident, you may have rights under the California Consumer Privacy Act and other applicable California privacy laws, including rights to request access to, correction of, or deletion of certain personal information, subject to applicable exceptions and limitations. Empowerreg does not sell personal information or share personal information for cross-context behavioral advertising.
If you are located in the European Economic Area or the United Kingdom and believe that we are unlawfully processing your personal information, you may have the right to lodge a complaint with your local data-protection supervisory authority.
If you are located in Switzerland, you may contact the Swiss Federal Data Protection and Information Commissioner.
The Services may integrate with or rely upon third-party services, including cloud providers, regulatory databases, product-registration databases, quality-management systems, artificial intelligence providers, analytics providers, communications providers, and other technology providers. We are not responsible for the privacy practices, content, availability, security, or operations of Third-Party Services. Your interactions with those third parties are governed by their own terms and privacy policies.
The Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from minors.
We may update this Privacy Policy from time to time. The updated version will be identified by a revised “Last Updated” date and will become effective when posted. If we make material changes, we may provide notice through the Services, by email, or by other appropriate means.
If you have questions regarding this Privacy Policy or our privacy practices, please contact us at:
Empowerreg Corp.
[Mailing Address]
Email: [–]